PT-2020-7062 · Smf · Smf

Brian Martin

+1

·

Published

2020-01-15

·

Updated

2020-01-23

·

CVE-2009-5068

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions SMF versions through v2.0.3
Description The issue allows co-admins in shared SMF deployments to read arbitrary files on the filesystem, potentially gaining new privileges by accessing sensitive information such as database passwords stored in settings.php. This is particularly concerning in configurations where co-admins are not fully trusted.
Recommendations For versions through v2.0.3, update to a version newer than v2.0.3 to resolve the issue. As a temporary workaround, consider restricting access to sensitive files such as settings.php to minimize the risk of exploitation.

Exploit

Fix

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-5068

Affected Products

Smf